THREAT OPS › Threat News › [NVD] CVE-2026-41862 (HIGH 8.8) — Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application
[NVD] CVE-2026-41862 (HIGH 8.8) — Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application
CVE-2026-41862 CVSS: 8.8 HIGH Published: 2026-06-23T21:16:57.820
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM.
Affected versions: Spring Statemachine 4.0.0 thr
Indicators of compromise
- CVE-2026-41862cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-41862